stable

nginx-1.28.1-1.fc44, nginx-mod-brotli-1.0.0~rc-4.fc44, & 5 more

FEDORA-2025-530e10091c created by heffer a month ago for Fedora 44

Changes with nginx 1.28.1 23 Dec 2025

*) Security: processing of a specially crafted login/password when using
   the "none" authentication method in the ngx_mail_smtp_module might
   cause worker process memory disclosure to the authentication server
   (CVE-2025-53859).

*) Bugfix: a segmentation fault might occur in a worker process if the
   "try_files" directive and "proxy_pass" with a URI were used.

*) Bugfix: in handling "Host" and ":authority" header lines with equal
   values when using HTTP/2; the bug had appeared in 1.17.9.

*) Bugfix: in handling "Host" header lines with a port when using
   HTTP/3.

*) Bugfix: an XCLIENT command didn't use the xtext encoding.
   Thanks to Igor Morgenstern of Aisle Research.

*) Bugfix: in SSL certificate caching during reconfiguration.

*) Bugfix: in delta-seconds processing in the "Cache-Control" backend
   response header line.

*) Change: the native nginx/Windows binary release is now built using
   Windows SDK 10.

*) Bugfix: nginx could not be built on NetBSD 10.0.

*) Bugfix: in HTTP/3.

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been submitted for stable by bodhi

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
0 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
approved
a month ago
BZ#2388411 CVE-2025-53859 nginx: NGINX ngx_mail_smtp_module vulnerability [fedora-42]
0
0

Automated Test Results